Command Injection Vulnerability in Cisco ASR 5000 Series Routers
CVE-2018-0115
6.7MEDIUM
Summary
An authenticated local attacker can exploit a vulnerability in the CLI of the Cisco StarOS operating system used in Cisco ASR 5000 Series routers. This vulnerability stems from inadequate validation of user-supplied input, allowing attackers to inject harmful command arguments into CLI commands. Successful exploitation provides attackers with the capability to execute arbitrary commands with root privileges, provided they authenticate with valid administrator credentials. This security flaw could lead to significant unauthorized control over the affected system.
Affected Version(s)
Cisco StarOS Cisco StarOS
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved